Privacy Policy
This policy describes the information VirtaBuilder processes, why we use it, which service providers receive it, and the choices available to you.
Effective and last updated: August 10, 20261. Scope and who is responsible
This Privacy Policy applies to virtabuilder.com, VirtaBuilder accounts, authenticated workspaces, AI-assisted deliverables, billing, transactional emails, and support interactions (the “Service”). VirtaBuilder is responsible for the personal information described here unless a business customer controls the information it places in a workspace. In that case, the business customer is responsible for its client data and VirtaBuilder processes that data to provide the Service on the customer’s instructions.
This policy does not govern websites or services that link to VirtaBuilder but operate under their own privacy notices.
2. Information we collect
Account and identity information
We process your email address, name, sign-in provider, account identifiers, login and invitation status, workspace membership, role, and basic profile information. Sign-in uses a Google account or a passwordless email link; VirtaBuilder does not ask you to create or store a password in the Service.
Workspace and business information
We process workspace and business names, niche, selected business template, plan, team configuration, AI agent settings, model choices, usage totals, bonus-credit balances, and administrative audit records.
Prompts, client briefs, and generated deliverables
When you create a deliverable, we process the brief and instructions you provide, related business context, the selected deliverable type, and the generated output. This material may contain personal information if you include it. You control what is submitted and should only provide information you are authorized to use.
Subscription and transaction information
We receive subscription plan, status, billing period, Stripe customer and subscription identifiers, and limited transaction information needed for support, fraud prevention, accounting, and entitlement management. Payment-card numbers and security codes are entered into Stripe-hosted payment pages and are not stored by VirtaBuilder.
Communications and support
We process messages sent to support, account-invitation and sign-in email events, and information you provide when asking for help, exercising a privacy right, or reporting a security concern.
Technical and security information
Our hosting, authentication, and payment providers may process IP address, browser and device type, timestamps, requested pages, session identifiers, diagnostic events, and fraud or security signals. We use this information to deliver pages, maintain sessions, prevent abuse, troubleshoot errors, and protect accounts.
3. How we use information
- authenticate users and maintain secure account sessions;
- create and administer private workspaces, roles, plans, and usage allowances;
- send briefs to selected AI models and store requested deliverables;
- process subscriptions, maintain plan access, and respond to billing questions;
- send sign-in links, account invitations, service notices, and support responses;
- detect fraud, enforce usage limits, investigate abuse, and secure the Service;
- debug failures, measure reliability, and improve workflows and usability;
- comply with legal, tax, accounting, and regulatory obligations; and
- establish, exercise, or defend legal claims and enforce our Terms.
4. AI processing and model providers
VirtaBuilder uses OpenRouter to route a deliverable request to the model configured for the relevant AI agent. The prompt sent for generation may include your brief, business context, instructions, and other Customer Content needed to produce the output. OpenRouter then transmits that request to the selected model provider.
OpenRouter states that it does not use API inputs or outputs to train its own models, but individual model providers have different logging, retention, and training policies. VirtaBuilder’s administrator can change the selected model, so the applicable provider can change. Review OpenRouter’s Privacy Policy and provider data-policy information. Do not include personal, confidential, or regulated information in a prompt unless you are authorized to have it processed by these providers.
5. Service providers and disclosures
We disclose information only as needed for the following purposes:
- Supabase provides authentication, database, and server infrastructure. See the Supabase Privacy Policy.
- Vercel hosts and delivers the web application and processes operational request logs. See the Vercel Privacy Notice.
- Stripe processes checkout, recurring payments, billing-portal activity, fraud signals, and payment records. See the Stripe Privacy Policy and Privacy Center.
- Brevo sends transactional email such as invitations and service communications. See the Brevo Privacy Policy.
- Google provides optional Google sign-in and returns basic identity and email information with your authorization. See the Google Privacy Policy.
- OpenRouter and model providers process prompts and outputs as described in the AI-processing section above.
We may also disclose information when required by valid legal process; to protect the rights, safety, property, or security of users, VirtaBuilder, or others; with your direction or consent; or in connection with a merger, financing, reorganization, or sale of all or part of the Service, subject to appropriate confidentiality protections.
VirtaBuilder does not sell personal information and does not share personal information for cross-context behavioral advertising. We do not use advertising trackers in the VirtaBuilder application at this time.
6. Cookies and similar technologies
We use essential cookies and local browser storage to maintain authentication, remember security state, and keep the Service functioning. When you proceed to Stripe checkout or the billing portal, Stripe may use cookies and device signals for payment, authentication, fraud prevention, and service analytics. You can block cookies in your browser, but essential functions such as sign-in may stop working.
7. Legal bases for processing
Where data-protection law requires a legal basis, we process information as necessary to perform our contract with you (account, workspace, AI generation, and billing); to comply with legal obligations; with your consent where requested; and for legitimate interests such as securing, supporting, and improving the Service, preventing fraud, and communicating about operational matters. We balance those interests against your rights and expectations. You may withdraw consent where consent is the basis, without affecting earlier lawful processing.
8. Data retention
We retain account, workspace, and deliverable information while the account is active and for a reasonable period afterward to complete deletion, resolve disputes, prevent fraud, restore backups, and meet legal obligations. Billing, credit-ledger, and audit records may be retained for the period required by tax, accounting, payment, or fraud laws. Support messages are retained as needed to resolve the request and document the outcome. Backup copies are removed on their normal secure-deletion cycle.
Third-party providers maintain their own retention schedules. Model-provider retention depends on the selected OpenRouter route and provider policy.
9. Security
We use measures designed to protect information, including encrypted HTTPS transport, passwordless or delegated authentication, restricted server credentials, tenant-level database access controls, protected administrator functions, and payment processing through Stripe rather than storing full card data. No internet service is completely secure, so we cannot guarantee that unauthorized access or loss will never occur. You are responsible for protecting access to your email and Google account and for signing out of shared devices.
10. International processing
VirtaBuilder and its providers operate internationally. Information may be processed in the United States and other countries with privacy laws different from those where you live. Where required, providers use recognized safeguards for international transfers, such as contractual protections or approved transfer frameworks.
11. Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about disclosures. You may also have the right to appeal a denied request and to avoid discrimination for exercising a privacy right. Because we do not sell personal information or use it for targeted advertising, there is no sale or targeted-advertising opt-out required for current VirtaBuilder practices.
Send requests to support@virtabuilder.comfrom the email associated with your account. We will verify the request and respond within the period required by applicable law. If your data was submitted by a VirtaBuilder business customer, we may direct the request to that customer because it controls the workspace data. You may also complain to your local privacy or data protection authority.
12. Children
The Service is designed for adults operating businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
13. Changes to this policy
We may update this policy when our practices, providers, products, or legal obligations change. The effective date at the top identifies the current version. We will provide additional notice of material changes through the Service or by email when appropriate.
14. Contact
For privacy questions, rights requests, account deletion, or security concerns, email support@virtabuilder.com. Include the account email and a clear description of the request, but do not send passwords, payment-card numbers, or other secrets by email.